Records and retention
How long do you have to keep visitor logs?
There is no single US retention period for visitor logs, and any page telling you the answer is five years is generalising one narrow regime to everybody. The period that binds you comes from whichever framework your site falls under. Here is what the main ones actually say.
This question gets answered badly online, usually by taking a rule written for classified facilities or federal tax data and presenting it as a universal requirement. It is not. Retention is set by the regime that applies to your site, and for most facilities more than one applies at once.
What the main regimes require
PCI DSS Requirement 9: three months
If your site has a room where cardholder data is stored or processed, PCI DSS requires a visitor log recording the visitor's name, the firm they represent, and the onsite personnel authorising access. The log must be retained for at least three months unless another law says longer. Badges must be visually distinguishable from employee badges, must expire, and must be surrendered on departure.
NERC CIP-006: 90 days
Utilities operating a Physical Security Perimeter under CIP-006 must log the date and time of initial entry and last exit, the visitor's name, and the name of the individual point of contact responsible for that visitor. Those logs are retained for at least ninety calendar days. The standard also requires continuous escorted access within the perimeter, which is a procedural duty rather than a records one.
State cannabis rules: four years, and the most prescriptive of all
Cannabis regulators write the most detailed visitor rules in the country. West Virginia, for example, requires the log to carry the visitor's full name, badge number, arrival time, departure time, and the purpose of the visit including which areas were entered and which employees were seen. Government ID must be checked against the name in the log, a photocopy of that ID retained with the log, and the whole record kept for four years. Ohio's dispensary rule runs parallel.
HIPAA: not what most vendors claim
HIPAA does not require a visitor log. Under 45 CFR 164.310(a), the facility access controls are Addressable rather than Required, and the phrase "including visitor control" sits inside the access control and validation specification. A visitor log is the usual way covered entities evidence that control, which is a different statement from the law demanding one. HIPAA's six-year documentation rule applies to policies and required documentation, not automatically to every visitor record.
SOC 2 and ISO 27001: no period, but a harder test
Neither prescribes fields or a retention period. What a SOC 2 Type II auditor tests is whether your stated visitor procedure was actually followed across the whole observation period. A log with gaps is worse than a short retention window, because it evidences that the control was not operating.
How to set a period you can defend
- Start from the longest requirement that applies to your site, not the shortest. A cannabis facility that also takes card payments is bound by four years, not three months.
- Write the period down as policy, with the regime it comes from named. An auditor asking why you keep records for a given period wants the reasoning, not just the number.
- Apply it automatically. A retention policy nobody enforces produces the worst outcome: years of data you were not required to keep, sitting in scope for any breach or subject-access request.
- Delete on schedule and be able to show that deletion happens. Under state privacy laws, holding personal data with no purpose is itself the exposure.
Where BeckonDesk fits
BeckonDesk holds a configurable retention period per tenant, defaulting to 90 days, and purges visitor records when it expires. Administrators set the window in settings to match whichever regime binds the site. The visit record carries the fields most of these frameworks ask for: visitor name, company, host name, check-in and check-out timestamps, badge number, purpose, and a photo where policy allows.
Related reading
See it on your own site.
A 30-minute walkthrough of sign-in, screening, and the record an auditor asks for. 30-day free trial, no credit card.